Vulnerability index

Browse CVEs

194 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper Access ControlCWE-284 × clear
Mac Os X Server MEDIUM 5.3
CVE-2016-1774

The Time Machine server in Server App in Apple OS X Server before 5.1 does not notify the user about ignored permissions during a backup, which makes…

Fix: after 5.0.15
Fix from $1,600 2016-03-24
Mac Os X MEDIUM 6.5
CVE-2016-1770

The Reminders component in Apple OS X before 10.11.4 allows attackers to bypass an intended user-confirmation requirement and trigger a dialing actio…

Fix: after 10.11.3
Fix from $1,600 2016-03-24
Tvos HIGH 9.3
CVE-2015-7055

AppleMobileFileIntegrity in Apple iOS before 9.2 and tvOS before 9.1 does not prevent changes to access-control structures, which allows attackers to…

Fix: after 9.1
Fix from $1,950 2015-12-11
Mac Os X HIGH 8.8
CVE-2015-6984

libarchive in Apple OS X before 10.11.1 allows attackers to write to arbitrary files via a crafted app that conducts an unspecified symlink attack.

Fix: after 10.11.0
Fix from $1,950 2015-10-23
Mac Os X MEDIUM 6.8
CVE-2015-5913

Heimdal, as used in Apple OS X before 10.11, allows remote attackers to conduct replay attacks against the SMB server via packet data that represents…

Fix: after 10.10.5
Fix from $1,600 2015-10-09
Watchos HIGH 7.2
CVE-2015-5882

The processor_set_tasks API implementation in Apple iOS before 9 allows local users to bypass an entitlement protection mechanism and obtain access t…

Fix: after 10.10.5
Fix from $1,950 2015-09-18
Iphone Os MEDIUM 5.0
CVE-2015-5746

AppleFileConduit in Apple iOS before 8.4.1 allows attackers to bypass intended restrictions on filesystem access via an afc command that leverages sy…

Fix: after 8.4
Fix from $1,600 2015-08-17
Iphone Os HIGH 7.2
CVE-2015-3806

Apple iOS before 8.4.1 and OS X before 10.10.5 allow local users to bypass a code-signing protection mechanism by appending code to a crafted executa…

Fix: after 10.10.4
Fix from $1,950 2015-08-17
Mac Os X MEDIUM 6.8
CVE-2015-3692

Apple Mac EFI before 2015-001, as used in OS X before 10.10.4 and other products, does not enforce a locking protection mechanism upon being woken fr…

Fix: after 10.10.3
Fix from $1,600 2015-07-03
Mac Os X HIGH 9.3
CVE-2015-3691

The Monitor Control Command Set kernel extension in the Display Drivers subsystem in Apple OS X before 10.10.4 allows attackers to execute arbitrary …

Fix: after 10.10.3
Fix from $1,950 2015-07-03
Mac Os X MEDIUM 5.0
CVE-2015-3675

The default configuration of the Apache HTTP Server on Apple OS X before 10.10.4 does not enable the mod_hfs_apple module, which allows remote attack…

Fix: after 10.10.3
Fix from $1,600 2015-07-03
Mac Os X HIGH 7.2
CVE-2015-3672

Admin Framework in Apple OS X before 10.10.4 does not properly handle authentication errors, which allows local users to obtain admin privileges via …

Fix: after 10.10.3
Fix from $1,950 2015-07-03
Mac Os X HIGH 7.2
CVE-2015-3671

Admin Framework in Apple OS X before 10.10.4 does not properly verify XPC entitlements, which allows local users to bypass authentication and obtain …

Fix: after 10.10.3
Fix from $1,950 2015-07-03
Os X Server MEDIUM 5.0
CVE-2015-1151

Wiki Server in Apple OS X Server before 4.1 allows remote attackers to bypass intended restrictions on Activity and People pages by connecting from a…

Fix: after 4.0
Fix from $1,600 2015-04-28